
wireshark
Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

Capture and analyze network traffic with deep packet inspection, protocol decoding across hundreds of protocols, and capture-file support for…

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Remote live forensics and incident response framework with Python agent for collecting forensic data from endpoints, including memory, disk, and…

Moneta is a live usermode memory analysis tool for Windows with the capability to detect malware IOCs

Dshell is a network forensic analysis framework.

Curated collection of cybersecurity resources, labs, and training materials covering ethical hacking, penetration testing, exploit development,…

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders


Forensic triage toolkit for Citrix NetScaler devices, featuring a Dissect-based IOC scanner for webshells, timestomping, and suspicious binaries,…

Utility that converts an .etl file containing a Windows network packet capture into .pcapng format.

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Open-source forensics framework for analyzing Industrial PLC metadata and project files. Scans for suspicious artifacts in ICS environments to…

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.


Indicator of Compromise Scanner for CVE-2019-19781

Python tool and library to help analyze files during malware triage and analysis.